TLDR: Malicious code in Trust Wallet Chrome extension version 2.68 stole seed phrases and drained $7 million total. Individual victims lost between $50,000 and $TLDR: Malicious code in Trust Wallet Chrome extension version 2.68 stole seed phrases and drained $7 million total. Individual victims lost between $50,000 and $

Trust Wallet Chrome Extension Hacked: $7M Stolen in Christmas Day Supply-Chain Attack

2025/12/26 22:54
3분 읽기
이 콘텐츠에 대한 의견이나 우려 사항이 있으시면 crypto.news@mexc.com으로 연락주시기 바랍니다

TLDR:

  • Malicious code in Trust Wallet Chrome extension version 2.68 stole seed phrases and drained $7 million total.
  • Individual victims lost between $50,000 and $800,000 across Bitcoin, Ethereum, and Solana blockchain networks.
  • Binance co-founder CZ confirmed Trust Wallet will reimburse all affected users and cover the complete $7M loss.
  • Users must avoid version 2.68 and upgrade to version 2.69 immediately; mobile wallets remained unaffected.

Trust Wallet suffered a major security breach on December 25 when malicious code infiltrated version 2.68 of its Chrome browser extension. 

The attack compromised user seed phrases and resulted in approximately $7 million in cryptocurrency losses across Bitcoin, Ethereum, and Solana networks. 

Binance co-founder Changpeng Zhao confirmed that affected users would receive full reimbursement for their losses.

Supply Chain Attack Targets Browser Extension Users

The breach occurred through a supply-chain attack that specifically targeted Trust Wallet’s Chrome extension update. Malicious actors injected code designed to steal seed phrases, which are crucial security elements that grant access to cryptocurrency holdings. 

Once compromised, these phrases allowed hackers to authorize transfers and drain funds from affected wallets.

On-chain investigators ZachXBT and Lookonchain tracked the stolen funds and confirmed their movement to various cryptocurrency exchanges. Individual losses ranged from $50,000 to $800,000 per victim. 

The timing of the attack, coinciding with the Christmas holiday, raised concerns about the coordinated nature of the breach.

Trust Wallet’s development team acted quickly upon discovering the compromise. The company released version 2.69 of the extension within hours and urged all users to upgrade immediately. 

Mobile wallet users and those using other browser extensions remained unaffected by the security incident.

Binance Pledges Full Coverage of User Losses

Changpeng Zhao, commonly known as CZ, addressed the incident through social media platforms. He stated that Trust Wallet would cover all losses incurred by affected users. His message emphasized that user funds remained secure despite the breach. 

CZ acknowledged the inconvenience caused while investigations continued into how the compromised version gained approval.

The wallet team issued urgent warnings advising users to avoid opening version 2.68 entirely. Instead, users should download and install version 2.69 immediately to protect their holdings. 

The company stressed that only Chrome extension users who updated to the compromised version faced potential exposure.

This incident reflects broader trends in cryptocurrency security challenges. According to Chainalysis, crypto theft reached $6.75 billion in 2024. 

Personal wallet compromises increased dramatically from 64,000 incidents in the previous year to 158,000 cases. However, the proportion of total stolen funds from personal wallets decreased from 44% to 20%.

Investigations remain ongoing to determine how hackers successfully submitted the malicious update through official channels. 

The breach highlights vulnerabilities in software distribution systems that cryptocurrency platforms must address. Trust Wallet continues working with security experts to prevent similar attacks in the future.

The post Trust Wallet Chrome Extension Hacked: $7M Stolen in Christmas Day Supply-Chain Attack appeared first on Blockonomi.

시장 기회
Intuition 로고
Intuition 가격(TRUST)
$0.06908
$0.06908$0.06908
+0.05%
USD
Intuition (TRUST) 실시간 가격 차트
면책 조항: 본 사이트에 재게시된 글들은 공개 플랫폼에서 가져온 것으로 정보 제공 목적으로만 제공됩니다. 이는 반드시 MEXC의 견해를 반영하는 것은 아닙니다. 모든 권리는 원저자에게 있습니다. 제3자의 권리를 침해하는 콘텐츠가 있다고 판단될 경우, crypto.news@mexc.com으로 연락하여 삭제 요청을 해주시기 바랍니다. MEXC는 콘텐츠의 정확성, 완전성 또는 시의적절성에 대해 어떠한 보증도 하지 않으며, 제공된 정보에 기반하여 취해진 어떠한 조치에 대해서도 책임을 지지 않습니다. 본 콘텐츠는 금융, 법률 또는 기타 전문적인 조언을 구성하지 않으며, MEXC의 추천이나 보증으로 간주되어서는 안 됩니다.

Roll the Dice & Win Up to 1 BTC

Roll the Dice & Win Up to 1 BTCRoll the Dice & Win Up to 1 BTC

Invite friends & share 500,000 USDT!